US8832452B2

System and method for implementing a trusted dynamic launch and trusted platform module (TPM) using secure enclaves

Summary by NHIP

Secure Enclave TPM Launch

The method initializes a secure enclave and executes a trusted platform module within it. A root key specific to the enclave is generated from native hardware data, including flags, platform unique keys, owner epoch values, and attestation primitives, to encrypt TPM data before reading platform control registers into the enclave's virtual memory region.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

An apparatus and method are described for implementing a trusted dynamic launch and trusted platform module (TPM) using a secure enclave. For example, a computer-implemented method according to one embodiment of the invention comprises: initializing a secure enclave in response to a first command, the secure enclave comprising a trusted software execution environment which prevents software executing outside the enclave from having access to software and data inside the enclave; and executing a trusted platform module (TPM) from within the secure enclave, the trusted platform module securely reading data from a set of platform control registers (PCR) in a processor or chipset component into a memory region allocated to the secure enclave.

US8832452B2, drawing sheet 1
Sheet 1 of 6

Term

6.5 yearsleft in the term

Expires 18 March 2033, including 817 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

27 claims: 3 independent, 24 dependent

  1. 1
    Broadest claimClaim Score 52, average(NHIP)A method implemented on a computing platform comprising:initializing a secure enclave in response to a first command, the secure enclave comprising a virtual memory region that defines a trusted software execution environment which prevents software executing outside the enclave from having access to software and data inside the enclave;generating a root key that is specific to the secure enclave, to encrypt data for a trusted platform module (TPM), the root key generated from different sets of data stored by native hardware components including a processor or chipset of the computing platform;and executing the trusted platform module from within the secure enclave using the root key, the trusted platform module securely reading data from a set of hardware platform control registers (pPCR) in the native hardware into the virtual memory region allocated to the secure enclave.
  2. 10
    An apparatus comprising a memory for storing program code and a processor for processing the program code to perform the operations of:initializing a secure enclave in response to a first command, the secure enclave comprising a virtual memory region that defines a trusted software execution environment which prevents software executing outside the enclave from having access to software and data inside the enclave;generating a trusted platform module root key that is specific to the secure enclave, to encrypt data for a trusted platform module (TPM), the root key generated from different sets of data stored by native hardware components including a processor or chipset of the computing platform;and executing the trusted platform module from within the secure enclave using the root key, the trusted platform module securely reading data from a set of hardware platform control registers (pPCR) in the native hardware into the virtual memory region allocated to the secure enclave.
  3. 19
    A non-transitory machine-readable medium having program code stored thereon which, when executed by a machine, causes the machine to perform the operations of:initializing a secure enclave in response to a first command, the secure enclave comprising a virtual memory region that defines a trusted software execution environment which prevents software executing outside the enclave from having access to software and data inside the enclave;generating a trusted platform module root key that is specific to the secure enclave, to encrypt data for a trusted platform module (TPM), the root key generated from different sets of data stored by native hardware components including a processor or chipset of the computing platform;and executing the trusted platform module from within the secure enclave using the root key, the trusted platform module securely reading data from a set of hardware platform control registers (pPCR) in the native hardware into the virtual memory region allocated to the secure enclave.